FlawAtlas
Search the atlas
ALSA-2022:2074 Not scored

Moderate: samba security, bug fix, and enhancement update

Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. The following packages have been upgraded to a later upstream version: samba (4.15.5). (BZ#2013596) Security Fix(es): * samba: Symlink race error can allow metadata read and modify outside of the exported share (CVE-2021-20316) * samba: Information leak via symlinks of existance of files or directories outside of the exported share (CVE-2021-44141) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Exploit probability Not scored
Published May 10, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 ctdb
AlmaLinux:8 libsmbclient
AlmaLinux:8 libsmbclient-devel
AlmaLinux:8 libwbclient
AlmaLinux:8 libwbclient-devel
AlmaLinux:8 python3-samba
AlmaLinux:8 python3-samba-test
AlmaLinux:8 samba
AlmaLinux:8 samba-client
AlmaLinux:8 samba-client-libs
AlmaLinux:8 samba-common
AlmaLinux:8 samba-common-libs
AlmaLinux:8 samba-common-tools
AlmaLinux:8 samba-devel
AlmaLinux:8 samba-krb5-printing
AlmaLinux:8 samba-libs
AlmaLinux:8 samba-pidl
AlmaLinux:8 samba-test
AlmaLinux:8 samba-test-libs
AlmaLinux:8 samba-vfs-iouring
AlmaLinux:8 samba-winbind
AlmaLinux:8 samba-winbind-clients
AlmaLinux:8 samba-winbind-krb5-locator
AlmaLinux:8 samba-winbind-modules
AlmaLinux:8 samba-winexe

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2022:2074

Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information. The following packages have been upgraded to a later upstream version: samba (4.15.5). (BZ#2013596) Security Fix(es): * samba: Symlink race error can allow metadata read and modify outside of the exported share (CVE-2021-20316) * samba: Information leak via symlinks of existance of files or directories outside of the exported share (CVE-2021-44141) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

View original source

05 / REFERENCES

Further evidence